時価総額: $2.2391T 1.66%
ボリューム(24時間): $47.003B 22.54%
  • 時価総額: $2.2391T 1.66%
  • ボリューム(24時間): $47.003B 22.54%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2391T 1.66%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

ホーム・デポのデータ侵害: GitHub トークンにより内部システムが 1 年間暴露され、セキュリティ上の懸念が浮上

2025/12/13 18:44

漏洩した GitHub トークンを含む Home Depot での重大なデータ侵害により、内部システムが 1 年近くにわたって暴露され、セキュリティ上の重大な問題が生じました。

ホーム・デポのデータ侵害: GitHub トークンにより内部システムが 1 年間暴露され、セキュリティ上の懸念が浮上

Home Depot Data Breach: GitHub Token Exposes Internal Systems for a Year, Prompting Security Concerns

ホーム・デポのデータ侵害: GitHub トークンにより内部システムが 1 年間暴露され、セキュリティ上の懸念が浮上

New York, NY - In a startling revelation that underscores the persistent vulnerabilities in corporate cybersecurity, Home Depot has been found to have left its internal systems exposed for nearly a year due to a leaked GitHub access token. This incident, which came to light recently, highlights significant gaps in the retail giant's security response protocols and its handling of responsible disclosure by researchers.

ニューヨーク州ニューヨーク - 企業のサイバーセキュリティにおける永続的な脆弱性を浮き彫りにする驚くべき事実として、Home Depot は、GitHub アクセス トークンの漏洩により、社内システムを 1 年近くにわたって放置していたことが判明しました。最近明らかになったこの事件は、小売大手のセキュリティ対応プロトコルと研究者による責任ある情報開示の扱いに大きなギャップがあることを浮き彫りにしている。

The Exposed Key to Home Depot's Digital Kingdom

ホームセンターのデジタル王国への鍵が明らかに

The saga began earlier in 2024 when a security expert, Ben Zimmermann, stumbled upon a private GitHub access token belonging to a Home Depot employee. This token, likely published by mistake, served as a digital master key, granting extensive access to hundreds of Home Depot's private source code repositories. The implications were far-reaching, potentially allowing unauthorized individuals to view, and even modify, critical code that governs everything from cloud infrastructure and order fulfillment to inventory management and development pipelines. Given Home Depot's reliance on GitHub for its engineering since 2015, the exposure represented a significant risk.

この物語は、2024 年の初めに、セキュリティ専門家であるベン ジマーマン氏が、ホームセンターの従業員が所有するプライベート GitHub アクセス トークンを偶然見つけたときに始まりました。このトークンはおそらく誤って公開されたもので、デジタル マスター キーとして機能し、Home Depot の何百ものプライベート ソース コード リポジトリへの広範なアクセスを許可しました。影響は広範囲に及び、クラウドインフラストラクチャや注文処理から在庫管理や開発パイプラインに至るまで、あらゆるものを管理する重要なコードを権限のない個人が閲覧したり、さらには変更できるようになる可能性もあった。 Home Depot が 2015 年以来、エンジニアリングで GitHub に依存していたことを考えると、この暴露は重大なリスクを意味しました。

A Year of Silence: Failed Disclosure and Media Intervention

沈黙の一年: 情報開示の失敗とメディア介入

What makes this data breach risk particularly alarming is the company's apparent lack of response to the researcher's warnings. Zimmermann reported the flaw responsibly, sending multiple emails to Home Depot's security contacts and even reaching out to their Chief Information Security Officer on LinkedIn. However, his attempts to alert the company were met with silence for weeks. "Home Depot is the only company that ignored me," Zimmermann stated, noting the absence of a formal bug bounty program which made the disclosure process more challenging. It wasn't until Zimmermann contacted TechCrunch that the company took action. Upon being approached by the news outlet on December 5, the token was promptly revoked. This intervention, nearly a year after the initial exposure, raises questions about whether malicious actors may have exploited the vulnerability during that extended period.

このデータ侵害のリスクを特に憂慮すべきものにしているのは、研究者の警告に対して同社が明らかに対応していないことだ。ジマーマン氏は責任を持ってこの欠陥を報告し、Home Depot のセキュリティ担当者に複数の電子メールを送信し、LinkedIn で最高情報セキュリティ責任者に連絡を取ることもしました。しかし、彼の会社への警告の試みは数週間にわたって沈黙に終わりました。 「私を無視したのはホーム・デポだけだ」とジマーマン氏は述べ、正式なバグ報奨金プログラムがないことが開示プロセスをさらに困難にしていると指摘した。 Zimmermann氏がTechCrunchに連絡を取って初めて、同社は行動を起こした。 12 月 5 日に報道機関から問い合わせがあり、トークンは直ちに取り消されました。最初の暴露からほぼ 1 年後に行われたこの介入により、悪意のある攻撃者がその長期間の間に脆弱性を悪用した可能性があるかどうかについて疑問が生じています。

Broader Implications and Lessons Learned

より広範な意味と教訓

While Home Depot's systems are now reportedly secure, the incident brings into sharp focus the critical importance of robust security response mechanisms. The prolonged period of exposure, coupled with the company's initial lack of engagement with the researcher, paints a concerning picture. Unlike e-commerce giant Coupang, which recently confirmed a data breach affecting millions of accounts and is facing legal action, Home Depot's situation appears to have been averted from a full-blown breach through external intervention. However, the near miss serves as a potent reminder for all organizations. The security expert's findings suggest that a malicious actor could have gained access to and altered internal software managing vital operations. While Home Depot has not commented on whether access logs were reviewed to ascertain potential misuse, the public exposure point is now closed.

Home Depot のシステムは現在安全であると伝えられていますが、この事件は堅牢なセキュリティ対応メカニズムの重要性を浮き彫りにしました。長期間にわたる暴露と、同社が当初研究者との関与を欠いていたことと相まって、懸念すべき状況が描かれている。最近数百万のアカウントに影響を与えるデータ侵害を確認し、法的措置に直面している電子商取引大手クーパンとは異なり、ホーム・デポの状況は外部介入により本格的な侵害は回避されたようだ。ただし、ニアミスはすべての組織にとって強力な注意喚起として機能します。セキュリティ専門家の調査結果は、悪意のある攻撃者が重要な業務を管理する内部ソフトウェアにアクセスして改ざんした可能性があることを示唆しています。ホーム・デポは、悪用の可能性を確認するためにアクセス・ログが調査されたかどうかについてコメントしていないが、公開ポイントは現在閉鎖されている。

So, the next time you're grabbing supplies from Home Depot, remember that while your purchases are safe, the digital keys to their kingdom were once out in the open for all to see. It's a good thing we have vigilant researchers keeping an eye on things, otherwise, who knows what kind of digital shenanigans could have unfolded!

したがって、次回ホームセンターで物資を購入するときは、購入したものは安全ですが、彼らの王国へのデジタルキーはかつては誰の目にも明らかなまま公開されていたことを思い出してください。用心深い研究者が物事を監視しているのは良いことですが、そうでなければ、どのようなデジタル詐欺が展開されるか誰にもわかりません。

オリジナルソース:zoombangla

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月27日 に掲載されたその他の記事